Klaussilveira · Gitlist · CVE-2026-82668
**Name of the Vulnerable Software and Affected Versions**
klaussilveira GitList version 2.0.0
**Description**
An OS command injection flaw exists in the Git Command Line component. The issue resides within the `getDefaultBranch()` function located in the `src/SCM/System/Git/CommandLine.php` file, which allows a remote attacker to execute arbitrary operating system commands.
**Recommendations**
Upgrade to version 3.0.0-beta.
As a temporary mitigation, restrict access to the `getDefaultBranch()` function.